Deepfake Fraud in e-KYC: How It Works and How to Stop It

Deepfake Fraud in e-KYC: How It Works and How to Stop It

Written by

August 3, 2026

A fraudster no longer needs to fool a person. They need to fool a camera, and increasingly, they don’t even need the camera at all.

Electronic Know Your Customer (e-KYC) is the digital ID check that lets someone open an account, apply for a loan, or register as a seller without visiting a branch. It’s become the front door to Indonesia’s digital economy, and now its most targeted door.

In one documented case, a major Indonesian financial institution faced over 1,100 deepfake fraud attempts against its digital KYC process in a few months, with potential losses estimated at $138.5 million, according to Group-IB. The attackers never visited a branch, and in many cases never even showed their real face to a camera.

This isn’t a future risk, it’s already happening, and it’s growing faster than most e-commerce platforms and micro-lenders in Indonesia are ready for.

What Is e-KYC?

e-KYC is the digital version of the ID checks banks have always run. Instead of showing a physical ID to a staff member, a customer uploads a photo of their ID and takes a live selfie. The system checks that the two match, and that a real person, not a photo or recording, is actually there.

In Indonesia, e-KYC isn’t optional for regulated platforms. Under OJK Circular Letter No. 12/SEOJK.03/2022, fintech lenders and digital financial services must use e-KYC to verify customers remotely, and POJK 8/2023 adds stricter checks for higher-risk platforms.

A robust architecture for eKYC Indonesia deployments relies on two main components:

  • Document Verification: Confirms the validity and authenticity of the submitted government ID.
  • Liveness Detection & Biometric Verification: Confirms the individual on camera is a live human matching the ID through advanced biometric verification.

However, standard liveness detection is precisely the layer that modern generative tools are engineered to bypass.

How Deepfake Fraud Beats e-KYC

There are two ways an attacker gets a fake face past a verification system, and each needs a different defence.

1. Presentation Attacks

A presentation attack shows something fake to the camera, a printed photo, a video on a second screen, or a mask. Liveness detection was built to catch exactly this, checking for the texture and depth a real face has and a flat image doesn’t.

2. Injection Attacks

An injection attack skips the camera entirely. The attacker feeds a fabricated video directly into the software, using a virtual camera driver or by tampering with the data itself. The system receives a stream that looks exactly like a real feed, with no way to tell it never came from a lens.

Understanding how adversaries execute deepfake fraud through software injection highlights why traditional camera-facing checks fall short.

A Real Case: 1,100 Deepfake Fraud Attempts in Indonesia

In 2024, a major Indonesian financial institution, one that already had layered security in place, was hit by a sustained deepfake fraud campaign against its loan application process.

Attackers first got hold of victims’ ID documents through malware, social media, and the dark web. They altered the photos, then used AI-generated deepfake images to pass the bank’s facial verification during loan sign-up.

Group-IB’s investigation found over 1,100 fraud attempts, more than 1,000 fraudulent accounts, and 45 devices used in the campaign, mostly Android. With an average fraudulent loan of $5,000, the estimated exposure reached $138.5 million over three months.

What makes this worth learning from: it happened despite real security already in place. The attackers won by targeting the gap between what liveness detection checks for and what an injection attack actually does, a gap that likely still exists at many platforms today.

It isn’t isolated either. Separate Group-IB intelligence recorded 8,065 attempts to bypass one institution’s liveness checks between January and August 2025 alone, an active, ongoing fraud operation, not a one-off.

Why E-Commerce and Micro-Lenders Are Especially at Risk

Deepfake fraud against e-KYC doesn’t hit every business the same way. It concentrates wherever verification has to be fast, where fraud converts easily into cash, and where sign-up volume makes manual review impossible.

  • Speed is the product. Micro-lending and buy-now-pay-later platforms compete on approving loans or purchases within minutes, and that speed works against thorough checks.
  • Loan fraud pays out in cash. A fraudulent order nets goods worth the purchase price. A fraudulent loan converts straight into cash, with nothing to ship or reverse.
  • Sellers get checked too. A fake seller identity opens the door to listing fraud, payment fraud, and using the platform’s own trust to scam real customers.
  • High volume means less scrutiny. Platforms handling thousands of daily sign-ups can’t manually review each one, which is exactly where injection attacks go unnoticed.

Defences Against Camera Injection and Deepfake Fraud

Standard liveness detection alone isn’t enough. Stopping these attacks takes a layered approach that checks whether the entire video feed can be trusted, not just the image.

1. Confirm the video is coming from a real camera

The single most important defence: checking that a stream actually came from a real device camera, not a virtual driver or an injected fake. There’s now a technical standard for it, CEN/TS 18099, built for detecting injection attacks.

2. Check for signs only a real body produces

Some signals are extremely hard for AI to fake: tiny skin color changes from blood flow (remote photoplethysmography) and genuine 3D facial depth. These don’t depend on a scripted prompt, which is what makes them hard to prepare for.

3. Use random checks, not predictable ones

A fixed prompt like “blink” can be scripted and faked ahead of time, since the attacker knows exactly what’s expected. Random checks generated fresh at the moment of the session close that gap, since there’s nothing to prepare in advance.

4. Match the ID and selfie in one uninterrupted step

Checking the ID and the live selfie together, in one unbroken session, closes the gap injection attacks exploit. Two disconnected checks only need to be beaten separately; one bound session has to be beaten as a whole.

5. Look at the whole video, not just one frame

A real video stays consistent across every frame. A fake one tends to drift or repeat in ways a single snapshot won’t reveal. Checking the whole stream catches inconsistencies a single-frame check would miss.

6. Detect fake cameras and emulators

Detecting whether a session runs through a virtual camera, an emulator, or a rooted phone flags many injection attempts before the facial check even starts, since these tools are what make the attack possible.

Indonesia’s Rules on Digital Identity Verification

OJK requires fintech and digital lending platforms to use e-KYC under Circular Letter No. 12/SEOJK.03/2022, with POJK 8/2023 adding stricter checks for higher-risk services.

Bank Indonesia’s own rules point in the same direction, placing digital identity verification at the center of the national payment system under its Payment System Blueprint (BSPI) 2030. PPATK oversees the anti-money laundering side, since a broken KYC process is a money laundering risk too, not just a fraud one.

For platforms, a deepfake-driven e-KYC failure isn’t just a financial loss, it’s a compliance failure on top of it.

Regulatory Frameworks on Digital Identity Verification

Financial authorities enforce strict compliance rules regarding remote customer verification. OJK Circular Letter No. 12/SEOJK.03/2022 mandates robust onboarding controls, with POJK 8/2023 requiring heightened diligence for high-risk financial activities.

In parallel, Bank Indonesia places secure identity verification at the core of its Payment System Blueprint (BSPI) 2030. Furthermore, PPATK monitors verification processes under Anti-Money Laundering (AML) frameworks, as compromised onboarding directly creates financial crime liabilities.

For platforms, a deepfake-driven e KYC failure represents both an immediate financial loss and a serious regulatory breach.

Staying Ahead of Synthetic Identity Fraud

As generative models advance, static onboarding checks will continue to degrade in effectiveness. Organisations must treat identity assurance as a continuous monitoring process rather than a point-in-time check to combat synthetic identity fraud.

That means watching for patterns a single check can’t see: several applications from the same device, unusual sign-up timing, and behavior that only shows up when sessions are viewed together.

Zentara’s Managed SOC provides continuous visibility beyond initial onboarding, integrating advanced fraud detection algorithms to identify automated account takeover attempts and post-verification anomalies. Supported by certified security analysts and a 15-minute SLA for critical incidents, Zentara ensures your verification pipelines remain secure against evolving synthetic threats.

The real question isn’t whether your liveness check can catch a photo held up to a camera. It’s whether it can tell the difference between a real camera and one that was never there.

Talk to Zentara to find out.

Frequently Asked Questions

1. What is the difference between a presentation attack and an injection attack?

A presentation attack shows something fake to the camera, like a printed photo. An injection attack skips the camera entirely, feeding fabricated video straight into the software, which is why standard liveness checks often miss it.

2. Can liveness detection alone stop deepfake fraud?

A presentation attack shows something fake to the camera, like a printed photo. An injection attack skips the camera entirely, feeding fabricated video straight into the software, which is why standard liveness checks often miss it.

3. How common is deepfake fraud against e-KYC in Indonesia?

It’s active and growing. A documented case at a major Indonesian financial institution found over 1,100 deepfake fraud attempts in a few months, with potential losses estimated at $138.5 million.

4. Is e-KYC required by law in Indonesia?

Yes, for regulated financial platforms, under OJK Circular Letter No. 12/SEOJK.03/2022, with extra checks required under POJK 8/2023 for higher-risk services.

Watch our FREE webinar: AI vs. Hackers - The Cyber Battle You Didn’t Know Was Happening

Marsha Widagdo, Zentara’s Head of Security Operations (Blue Team), will break down how defenders use AI to spot, triage, and contain real threats—and how attackers are weaponising it in return. Expect practical playbooks, recent cases, and clear steps you can apply.

Where Cybersecurity Meets Community

We’re building a space for cybersecurity practitioners, students, researchers, and enthusiasts to connect, learn, exchange ideas, and grow as a collective. A community built around discourse, industry insights, and driven by mutual goals.

Modern Cybersecurity Services, Built for Complexity

From threat intelligence to vulnerability assessments and incident response, Zentara helps governments and enterprises stay ahead of every attack vector